refactor (by Qwen)

This commit is contained in:
2026-08-06 17:17:10 -07:00
parent 0a08e5176f
commit 153ff43cf5
+157 -234
View File
@@ -1,3 +1,7 @@
# =============================================================================
# Torrent Stack - Docker Compose
# =============================================================================
networks: networks:
caddy_net: caddy_net:
external: true external: true
@@ -13,59 +17,49 @@ volumes:
caddy_data: caddy_data:
external: true external: true
myspeed: myspeed:
external: true # docker compose will fail creating myspeed if the volume hasn't been manually created, which we have done. unless you deleted it... external: true
portainer_data: portainer_data:
name: portainer_data
##### ORGANIZATION FOR EVERY CONTAINER # =============================================================================
# services: # Key ordering per service:
# container: # image → container_name → env_file → networks/network_mode → cap_add
# image: <...> # → ports → volumes → environment → labels → healthcheck
# container_name: <...> # → extra_hosts → devices → pid → restart
# env_file: <...> # =============================================================================
# networks: <...>
# cap_add: <...>
# ports: <...>
# volumes: <...>
# environment: <...>
# labels: <...>
# healthcheck: <...>
# extra_hosts: <...>
# restart: <...>
#
services: services:
# ---------------------------------------------------------------------------
# VPN & Download
# ---------------------------------------------------------------------------
gluetun: gluetun:
image: qmcgaw/gluetun:latest image: qmcgaw/gluetun:latest
container_name: gluetun container_name: gluetun
cap_add: cap_add:
- NET_ADMIN - NET_ADMIN
ports: # YOU MUST SPECIFY A PORT PER SERVICE ROUTED THROUGH GLUETUN! ports:
- 8888:8000/tcp # gluetun control server, i dont think you should change this - 8888:8000/tcp
- ${QBITTORRENT_PORT}:${QBITTORRENT_PORT} # qBittorrent Web UI - ${QBITTORRENT_PORT}:${QBITTORRENT_PORT}
- ${PROWLARR_PORT}:${PROWLARR_PORT} # Prowlarr - ${PROWLARR_PORT}:${PROWLARR_PORT}
- ${SONARR_PORT}:${SONARR_PORT} # Sonarr - ${SONARR_PORT}:${SONARR_PORT}
- ${RADARR_PORT}:${RADARR_PORT} # Radarr - ${RADARR_PORT}:${RADARR_PORT}
- ${LIDARR_PORT}:${LIDARR_PORT} # Lidarr - ${LIDARR_PORT}:${LIDARR_PORT}
#- ${SEERR_PORT}:${SEERR_PORT}/tcp # Seerr # took this out of gluetun, as it could cause issues with starting the container, and it was unecessary
volumes: volumes:
- ./gluetun-data:/tmp/gluetun:rw - ./gluetun-data:/tmp/gluetun:rw
environment: environment:
- VPN_SERVICE_PROVIDER=protonvpn # Or mullvad, protonvpn, surfshark, etc. - VPN_SERVICE_PROVIDER=protonvpn
- VPN_TYPE=wireguard # WireGuard, openvpn - VPN_TYPE=wireguard
- HTTP_CONTROL_SERVER=ON - HTTP_CONTROL_SERVER=ON
- HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE='{"auth":"apikey","apikey":"${GLUETUN_KEY}"}' # generate by running `docker run --rm qmcgaw/gluetun genkey`, then adding this to your `.env` file - HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE='{"auth":"apikey","apikey":"${GLUETUN_KEY}"}'
- WIREGUARD_PRIVATE_KEY=${VPN_PRIVATE_KEY} - WIREGUARD_PRIVATE_KEY=${VPN_PRIVATE_KEY}
- WIREGUARD_MTU=1280 - WIREGUARD_MTU=1280
- VPN_PORT_FORWARDING=on - VPN_PORT_FORWARDING=on
- VPN_PORT_FORWARDING_PROVIDER=protonvpn - VPN_PORT_FORWARDING_PROVIDER=protonvpn
#- OPENVPN_USER=user - SERVER_COUNTRIES=Netherlands
#- OPENVPN_PASSWORD=password
- SERVER_COUNTRIES=Netherlands # choose fast P2P friendly countries
- NETWORK_LOCAL_ADDRESSES=192.168.50.0/24,172.16.0.0/12 - NETWORK_LOCAL_ADDRESSES=192.168.50.0/24,172.16.0.0/12
- FIREWALL_OUTBOUND_SUBNETS=192.168.50.0/24 - FIREWALL_OUTBOUND_SUBNETS=192.168.50.0/24
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
- DNS_UPSTREAM_RESOLVER_TYPE=doh # DNS over TLS is an extra layer of security so your isp can not look at what you're doing through your DNS requests, even if your using a vpn (very vague, I don't know how this syustem works with a vpn). - DNS_UPSTREAM_RESOLVER_TYPE=doh
healthcheck: healthcheck:
test: wget --spider -q http://1.1.1.1 || exit 1 test: wget --spider -q http://1.1.1.1 || exit 1
interval: 30s interval: 30s
@@ -73,7 +67,7 @@ services:
retries: 3 retries: 3
start_period: 1m start_period: 1m
extra_hosts: extra_hosts:
- "host.docker.internal:host-gateway" # host-gateway is a docker variable that automatically grabs the 172.XX.0.1 address, this is to be used by prowlarr to communicate with sonarr and radarr. - "host.docker.internal:host-gateway"
devices: devices:
- /dev/net/tun:/dev/net/tun - /dev/net/tun:/dev/net/tun
restart: always restart: always
@@ -81,12 +75,10 @@ services:
qbittorrent: qbittorrent:
image: lscr.io/linuxserver/qbittorrent:latest image: lscr.io/linuxserver/qbittorrent:latest
container_name: qbittorrent container_name: qbittorrent
network_mode: "container:gluetun" # vpn bunker network_mode: "container:gluetun"
depends_on: depends_on:
gluetun: gluetun:
condition: service_healthy condition: service_healthy
labels:
- "autoheal=true"
volumes: volumes:
- ./qbittorrent:/config - ./qbittorrent:/config
- ${DISK1}:${DISK1} - ${DISK1}:${DISK1}
@@ -99,8 +91,10 @@ services:
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
- WEBUI_PORT=${QBITTORRENT_PORT} - WEBUI_PORT=${QBITTORRENT_PORT}
healthcheck: # if gluetun is slow to start, it's over labels:
test: ["CMD-SHELL", wget --spider -q https://1.1.1.1 || exit 1] # use 1.1.1.1, we don't need dns around here - "autoheal=true"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q https://1.1.1.1 || exit 1"]
interval: 1m interval: 1m
timeout: 10s timeout: 10s
retries: 3 retries: 3
@@ -108,47 +102,38 @@ services:
restart: unless-stopped restart: unless-stopped
port-updater: port-updater:
# use an image that already has curl/wget to skip the 'apk add' step
image: curlimages/curl:latest image: curlimages/curl:latest
container_name: port-updater container_name: port-updater
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
volumes: volumes:
- ./gluetun-data:/tmp/gluetun:ro - ./gluetun-data:/tmp/gluetun:ro
# using 'exec' format and 'trap' allows the container to stop instantly
entrypoint: ["/bin/sh", "-c"] entrypoint: ["/bin/sh", "-c"]
command: # loololloloolol gemini did this for me command:
- | - |
trap 'exit 0' SIGTERM; trap 'exit 0' SIGTERM;
while true; do while true; do
# 1. Wait for Gluetun to actually create the file with a number
while [ ! -s /tmp/gluetun/forwarded_port ]; do while [ ! -s /tmp/gluetun/forwarded_port ]; do
echo "Waiting for Gluetun to provide a port..." echo "Waiting for Gluetun to provide a port..."
sleep 5 sleep 5
done done
# 2. Read and clean the port
read -r PORT_VAL < /tmp/gluetun/forwarded_port; read -r PORT_VAL < /tmp/gluetun/forwarded_port;
CLEAN_PORT=$$(echo "$$PORT_VAL" | tr -d '\r\n '); CLEAN_PORT=$$(echo "$$PORT_VAL" | tr -d '\r\n ');
# 3. Only update if the port isn't empty
if [ -n "$$CLEAN_PORT" ]; then if [ -n "$$CLEAN_PORT" ]; then
echo "Updating qBit to port: $$CLEAN_PORT"; echo "Updating qBit to port: $$CLEAN_PORT";
sleep 10; sleep 10;
echo "Updated to $$CLEAN_PORT"
curl -s -X POST -d "json={\"listen_port\":$$CLEAN_PORT}" http://localhost:${QBITTORRENT_PORT}/api/v2/app/setPreferences; curl -s -X POST -d "json={\"listen_port\":$$CLEAN_PORT}" http://localhost:${QBITTORRENT_PORT}/api/v2/app/setPreferences;
# 4. Success! Now sleep for a long time (e.g., 1 hour)
sleep 3600 & wait $$!; sleep 3600 & wait $$!;
else else
# If for some reason it's still blank, retry quickly
sleep 10 sleep 10
fi fi
done done
labels: labels:
- "autoheal=true" - "autoheal=true"
network_mode: "container:gluetun"
depends_on:
gluetun:
condition: service_healthy
healthcheck: healthcheck:
test: ["CMD-SHELL", "curl -f https://1.1.1.1 || exit 1"] test: ["CMD-SHELL", "curl -f https://1.1.1.1 || exit 1"]
interval: 1m interval: 1m
@@ -157,6 +142,10 @@ services:
start_period: 30s start_period: 30s
restart: always restart: always
# ---------------------------------------------------------------------------
# *arr Stack
# ---------------------------------------------------------------------------
prowlarr: prowlarr:
image: lscr.io/linuxserver/prowlarr:latest image: lscr.io/linuxserver/prowlarr:latest
container_name: prowlarr container_name: prowlarr
@@ -164,8 +153,6 @@ services:
depends_on: depends_on:
gluetun: gluetun:
condition: service_healthy condition: service_healthy
labels:
- "autoheal=true"
volumes: volumes:
- ./prowlarr:/config - ./prowlarr:/config
- ./notify.sh:/notify.sh:ro - ./notify.sh:/notify.sh:ro
@@ -175,8 +162,10 @@ services:
- PUID=${HOST_PUID:-1000} - PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
labels:
- "autoheal=true"
healthcheck: healthcheck:
test: ["CMD-SHELL", wget --spider -q https://google.com || exit 1] # needs DNS test: ["CMD-SHELL", "wget --spider -q https://google.com || exit 1"]
interval: 5m interval: 5m
timeout: 60s timeout: 60s
retries: 3 retries: 3
@@ -190,10 +179,8 @@ services:
depends_on: depends_on:
gluetun: gluetun:
condition: service_healthy condition: service_healthy
labels:
- "autoheal=true"
volumes: volumes:
- /var/lib/sonarr:/config # had migrated into docker compose - /var/lib/sonarr:/config
- ${DISK1}:${DISK1} - ${DISK1}:${DISK1}
- ${DISK2}:${DISK2} - ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
@@ -202,6 +189,8 @@ services:
- PUID=${HOST_PUID:-1000} - PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
labels:
- "autoheal=true"
healthcheck: healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"] test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 5m interval: 5m
@@ -214,13 +203,11 @@ services:
image: lscr.io/linuxserver/radarr:latest image: lscr.io/linuxserver/radarr:latest
container_name: radarr container_name: radarr
network_mode: "container:gluetun" network_mode: "container:gluetun"
labels:
- "autoheal=true"
depends_on: depends_on:
gluetun: gluetun:
condition: service_healthy condition: service_healthy
volumes: volumes:
- /var/lib/radarr:/config # had migrated into docker compose - /var/lib/radarr:/config
- ${DISK1}:${DISK1} - ${DISK1}:${DISK1}
- ${DISK2}:${DISK2} - ${DISK2}:${DISK2}
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
@@ -229,6 +216,8 @@ services:
- PUID=${HOST_PUID:-1000} - PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
labels:
- "autoheal=true"
healthcheck: healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"] test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 1m interval: 1m
@@ -244,8 +233,6 @@ services:
depends_on: depends_on:
gluetun: gluetun:
condition: service_healthy condition: service_healthy
labels:
- "autoheal=true"
volumes: volumes:
- ./lidarr:/music - ./lidarr:/music
- /var/lib/lidarr:/config - /var/lib/lidarr:/config
@@ -257,6 +244,8 @@ services:
- PUID=${HOST_PUID:-1000} - PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
labels:
- "autoheal=true"
healthcheck: healthcheck:
test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"] test: ["CMD-SHELL", "curl -f http://1.1.1.1 || exit 1"]
interval: 1m interval: 1m
@@ -265,7 +254,11 @@ services:
start_period: 30s start_period: 30s
restart: unless-stopped restart: unless-stopped
tautulli: # has no network bridge between containers. this is fine, as it only needs to get from plex, which is outside this container # ---------------------------------------------------------------------------
# Media
# ---------------------------------------------------------------------------
tautulli:
image: ghcr.io/tautulli/tautulli image: ghcr.io/tautulli/tautulli
container_name: tautulli container_name: tautulli
networks: networks:
@@ -273,7 +266,6 @@ services:
ports: ports:
- ${TAUTULLI_PORT}:${TAUTULLI_PORT} - ${TAUTULLI_PORT}:${TAUTULLI_PORT}
volumes: volumes:
#- /mnt/media/media:/config
- ./tautulli:/config - ./tautulli:/config
environment: environment:
- PUID=${HOST_PUID:-1000} - PUID=${HOST_PUID:-1000}
@@ -287,8 +279,8 @@ services:
networks: networks:
- tdarr-net - tdarr-net
ports: ports:
- ${TDARR_PORT}:${TDARR_PORT} # WebUI - ${TDARR_PORT}:${TDARR_PORT}
- ${TDARR_NODE_PORT}:${TDARR_NODE_PORT} # local tdarr-node - ${TDARR_NODE_PORT}:${TDARR_NODE_PORT}
volumes: volumes:
- ./tdarr/server:/app/server - ./tdarr/server:/app/server
- ./tdarr/configs:/app/configs - ./tdarr/configs:/app/configs
@@ -301,9 +293,6 @@ services:
- PGID=${HOST_PGID:-100} - PGID=${HOST_PGID:-100}
- UMASK_SET=002 - UMASK_SET=002
- serverIP=0.0.0.0 - serverIP=0.0.0.0
# dont put temp files onto a HARD DISK DRIVE! > - ${DISK1}/tdarr-temp:/temp
#devices: #? I don't think this is needed
# - /dev/dri:/dev/dri # Intel UHD Graphics 710
restart: unless-stopped restart: unless-stopped
tdarr-node: tdarr-node:
@@ -314,7 +303,7 @@ services:
volumes: volumes:
- ./tdarr/configs:/app/configs - ./tdarr/configs:/app/configs
- ./tdarr/logs:/app/logs - ./tdarr/logs:/app/logs
- /home/shaan/torrent-stack/tdarr/temp:/temp - ./tdarr/temp:/temp
- ${DISK1}:${DISK1} - ${DISK1}:${DISK1}
- ${DISK2}:${DISK2} - ${DISK2}:${DISK2}
environment: environment:
@@ -323,12 +312,54 @@ services:
- PGID=${HOST_PGID:-1000} - PGID=${HOST_PGID:-1000}
- nodeID=${TDARR_NODE_ID} - nodeID=${TDARR_NODE_ID}
- nodeIP=0.0.0.0 - nodeIP=0.0.0.0
- serverIP=tdarr # Points to the server container - serverIP=tdarr
- serverPort=${TDARR_NODE_PORT} - serverPort=${TDARR_NODE_PORT}
devices: devices:
- /dev/dri/:/dev/dri/ # only works if user 'shaan' is a part of the 'video' or 'render' group. - /dev/dri/:/dev/dri/
restart: unless-stopped restart: unless-stopped
seerr:
image: ghcr.io/seerr-team/seerr:latest
container_name: seerr
networks:
- caddy_net
ports:
- ${SEERR_PORT}:${SEERR_PORT}
volumes:
- ./seerr:/app/config
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
- LOG_LEVEL=debug
- TZ=America/Los_Angeles
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
labels:
- "autoheal=true"
init: true
working_dir: "/app"
healthcheck:
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
restart: unless-stopped
seerr-anubis:
image: ghcr.io/techarohq/anubis:latest
container_name: seerr_anubis
networks:
- caddy_net
environment:
- BIND=:55055
- TARGET=http://seerr:${SEERR_PORT}
restart: unless-stopped
# ---------------------------------------------------------------------------
# Monitoring
# ---------------------------------------------------------------------------
homepage: homepage:
image: ghcr.io/gethomepage/homepage:latest image: ghcr.io/gethomepage/homepage:latest
container_name: homepage container_name: homepage
@@ -339,21 +370,18 @@ services:
volumes: volumes:
- ./homepage:/app/config - ./homepage:/app/config
- ./homepage/images:/app/public/images - ./homepage/images:/app/public/images
- /var/run/docker.sock:/var/run/docker.sock:ro # (optional) For docker integrations - /var/run/docker.sock:/var/run/docker.sock:ro
- ./gluetun-data:/tmp/gluetun:ro # get the port from port-updater - ./gluetun-data:/tmp/gluetun:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
environment: environment:
# INIT - "HOMEPAGE_ALLOWED_HOSTS=gethomepage.dev,${LOCAL_IPV4}:${HOMEPAGE_PORT},${SERVER_NAME}:${HOMEPAGE_PORT},${SERVER_NAME}.${TAILNET_NAME}:${HOMEPAGE_PORT}"
- "HOMEPAGE_ALLOWED_HOSTS=gethomepage.dev,${LOCAL_IPV4}:${HOMEPAGE_PORT},${SERVER_NAME}:${HOMEPAGE_PORT},${SERVER_NAME}.${TAILNET_NAME}:${HOMEPAGE_PORT}" # required, may need port. See gethomepage.dev/installation/#homepage_allowed_hosts
#\- "HOMEPAGE_ALLOWED_HOSTS=*"
- "HOMEPAGE_VAR_DISK1=${DISK1}" - "HOMEPAGE_VAR_DISK1=${DISK1}"
- "HOMEPAGE_VAR_DISK2=${DISK2}" - "HOMEPAGE_VAR_DISK2=${DISK2}"
- "HOMEPAGE_VAR_DISK3=${DISK3}" - "HOMEPAGE_VAR_DISK3=${DISK3}"
- "HOMEPAGE_VAR_WEB_PROTOCOL=${WEB_PROTOCOL}" - "HOMEPAGE_VAR_WEB_PROTOCOL=${WEB_PROTOCOL}"
- "HOMEPAGE_VAR_LOCAL_IPV4=${LOCAL_IPV4}" - "HOMEPAGE_VAR_LOCAL_IPV4=${LOCAL_IPV4}"
- "HOMEPAGE_VAR_SERVER_NAME=${SERVER_NAME}" - "HOMEPAGE_VAR_SERVER_NAME=${SERVER_NAME}"
# KEYS
- "HOMEPAGE_VAR_PLEX_KEY=${PLEX_KEY}" - "HOMEPAGE_VAR_PLEX_KEY=${PLEX_KEY}"
- "HOMEPAGE_VAR_PROWLARR_KEY=${PROWLARR_KEY}" - "HOMEPAGE_VAR_PROWLARR_KEY=${PROWLARR_KEY}"
- "HOMEPAGE_VAR_RADARR_KEY=${RADARR_KEY}" - "HOMEPAGE_VAR_RADARR_KEY=${RADARR_KEY}"
@@ -364,7 +392,6 @@ services:
- "HOMEPAGE_VAR_QBITTORRENT_KEY=${QBITTORRENT_KEY}" - "HOMEPAGE_VAR_QBITTORRENT_KEY=${QBITTORRENT_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_KEY=${TAILSCALE_KEY}" - "HOMEPAGE_VAR_TAILSCALE_KEY=${TAILSCALE_KEY}"
- "HOMEPAGE_VAR_TAILSCALE_DEVICE_KEY=${TAILSCALE_DEVICE_KEY}" - "HOMEPAGE_VAR_TAILSCALE_DEVICE_KEY=${TAILSCALE_DEVICE_KEY}"
# WEB ADDRESSES
- "HOMEPAGE_VAR_PLEX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PLEX_PORT}" - "HOMEPAGE_VAR_PLEX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${QBITTORRENT_PORT}" - "HOMEPAGE_VAR_QBITTORRENT_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PROWLARR_PORT}" - "HOMEPAGE_VAR_PROWLARR_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${PROWLARR_PORT}"
@@ -379,7 +406,6 @@ services:
- "HOMEPAGE_VAR_MYSPEED_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${MYSPEED_PORT}" - "HOMEPAGE_VAR_MYSPEED_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${MYSPEED_PORT}"
- "HOMEPAGE_VAR_TERMIX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TERMIX_PORT}" - "HOMEPAGE_VAR_TERMIX_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${TERMIX_PORT}"
- "HOMEPAGE_VAR_ODYSSEUS_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${ODYSSEUS_PORT}" - "HOMEPAGE_VAR_ODYSSEUS_ADDRESS=${WEB_PROTOCOL}://${LOCAL_IPV4}:${ODYSSEUS_PORT}"
# WEB NAMES
- "HOMEPAGE_VAR_PLEX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PLEX_PORT}" - "HOMEPAGE_VAR_PLEX_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PLEX_PORT}"
- "HOMEPAGE_VAR_QBITTORRENT_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${QBITTORRENT_PORT}" - "HOMEPAGE_VAR_QBITTORRENT_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${QBITTORRENT_PORT}"
- "HOMEPAGE_VAR_PROWLARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PROWLARR_PORT}" - "HOMEPAGE_VAR_PROWLARR_HOST=${WEB_PROTOCOL}://${SERVER_NAME}:${PROWLARR_PORT}"
@@ -402,7 +428,6 @@ services:
glances: glances:
image: nicolargo/glances:latest-full image: nicolargo/glances:latest-full
container_name: glances container_name: glances
pid: host
network_mode: host network_mode: host
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
@@ -417,6 +442,7 @@ services:
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
devices: devices:
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
pid: host
restart: unless-stopped restart: unless-stopped
autoheal: autoheal:
@@ -432,111 +458,60 @@ services:
- AUTOHEAL_START_PERIOD=60 - AUTOHEAL_START_PERIOD=60
restart: always restart: always
seerr: myspeed:
image: ghcr.io/seerr-team/seerr:latest image: germannewsmaker/myspeed
container_name: seerr container_name: myspeed
working_dir: "/app" # something idk
init: true
networks:
- caddy_net
labels:
- "autoheal=true"
ports: ports:
- ${SEERR_PORT}:${SEERR_PORT} - ${MYSPEED_PORT}:${MYSPEED_PORT}/tcp
volumes: volumes:
- "./seerr:/app/config" - myspeed:/myspeed/data
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
environment: environment:
- LOG_LEVEL=debug
- TZ=America/Los_Angeles
- PUID=${HOST_PUID:-1000}
- PGID=${HOST_PGID:-1000}
healthcheck:
test: ["CMD-SHELL", "wget --spider -q http://1.1.1.1 || exit 1"]
interval: 1m
timeout: 10s
retries: 3
start_period: 60s
restart: unless-stopped
seerr-anubis:
image: ghcr.io/techarohq/anubis:latest
container_name: seerr_anubis
networks:
- caddy_net
environment:
BIND: ":55055"
TARGET: http://seerr:${SEERR_PORT}
restart: unless-stopped
MySpeed:
image: "germannewsmaker/myspeed"
container_name: "MySpeed"
network_mode: "bridge"
ports:
- "${MYSPEED_PORT}:${MYSPEED_PORT}/tcp"
volumes:
- "myspeed:/myspeed/data"
- /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro
environment:
- "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
- "NODE_VERSION=18.20.3"
- "YARN_VERSION=1.22.19"
- "NODE_ENV=production"
- TZ=${TIMEZONE} - TZ=${TIMEZONE}
hostname: "4b5e3178fcc4"
ipc: "private"
logging:
driver: "json-file"
options: {}
mac_address: "02:42:ac:11:00:03"
working_dir: "/myspeed"
entrypoint:
- "docker-entrypoint.sh"
command:
- "node"
- "server"
restart: unless-stopped restart: unless-stopped
# termix: scrutiny:
# image: ghcr.io/lukegus/termix:latest image: ghcr.io/analogj/scrutiny:nightly-omnibus
# container_name: termix container_name: scrutiny
# cap_add: cap_add:
# - NET_ADMIN - SYS_RAWIO
# - SYS_ADMIN ports:
# networks: - ${SCRUTINY_PORT:-54321}:8080
# - termix-net - ${SCRUTINY_ADMIN_PORT:-12345}:8086
# ports: volumes:
# - "${TERMIX_PORT}:${TERMIX_PORT}" - /run/udev:/run/udev:ro
# volumes: - ./config:/opt/scrutiny/config
# - termix-data:/app/data - ./influxdb:/opt/scrutiny/influxdb
# environment: devices:
# - "PORT: ${TERMIX_PORT}" - /dev/nvme0n1
# - "TZ: {TIMEZONE}" - /dev/sda
# restart: unless-stopped restart: unless-stopped
# ---------------------------------------------------------------------------
# Infrastructure
# ---------------------------------------------------------------------------
pihole: pihole:
image: pihole/pihole:latest image: pihole/pihole:latest
container_name: pihole container_name: pihole
cap_add: cap_add:
- NET_ADMIN - NET_ADMIN
network_mode: "host" network_mode: host
ports: ports:
- "53:53/tcp" - 53:53/tcp
- "53:53/udp" - 53:53/udp
- "67:67/udp" - 67:67/udp
- "6060:6060/tcp" # original port '80' changed to '6060' within in the webui, be careful changing this - 6060:6060/tcp
volumes: volumes:
- "./etc-pihole:/etc/pihole" - ./etc-pihole:/etc/pihole
- "./etc-dnsmasq.d:/etc/dnsmasq.d" - ./etc-dnsmasq.d:/etc/dnsmasq.d
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
environment: environment:
TZ: "America/Los_Angeles" - TZ=America/Los_Angeles
WEBPASSWORD: "password123" - WEBPASSWORD=password123
FTLCONF_misc_etc_dnsmasq_d: "true" - FTLCONF_misc_etc_dnsmasq_d=true
restart: unless-stopped restart: unless-stopped
cloudflared: cloudflared:
@@ -545,47 +520,15 @@ services:
command: tunnel --no-autoupdate run --token ${CLOUDFLARED_KEY} command: tunnel --no-autoupdate run --token ${CLOUDFLARED_KEY}
restart: always restart: always
# torrents-csv:
# image: dessalines/torrents-csv-server:latest
# container_name: torrents-csv
# depends_on:
# - db # search at 'http://shaan-server:8902/service/search?q={SEARCH_TERM'
# ports:
# - "8902:8902"
# environment:
# TORRENTS_CSV_DB_HOST: "postgres://postgres:password@db"
# TORRENTS_CSV_FRONT_END_DIR: /app/dist
# RUST_LOG: DEBUG
# TIMEZONE: ${TIMEZONE}
# restart: unless-stopped
# db:
# image: pgautoupgrade/pgautoupgrade:17-alpine
# container_name: torrents-csv-db
# shm_size: 4gb
# ports:
# - "127.0.0.1:5433:5432"
# volumes:
# - ./init-database.sh:/docker-entrypoint-initdb.d/init-database.sh
# - ./init-database.sql:/var/lib/postgresql/init-database.sql
# - ./torrents.csv:/var/lib/postgresql/torrents.csv
# - /etc/localtime:/etc/localtime:ro
# - /etc/timezone:/etc/timezone:ro
# environment:
# POSTGRES_PASSWORD: password
# POSTGRES_USER: postgres
# TIMEZONE: ${TIMEZONE}
# restart: unless-stopped
portainer: portainer:
image: portainer/portainer-ce:lts image: portainer/portainer-ce:lts
container_name: portainer container_name: portainer
restart: always
ports: ports:
- ${PORTAINER_PORT}:${PORTAINER_PORT} - ${PORTAINER_PORT}:${PORTAINER_PORT}
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data - portainer_data:/data
restart: always
caddy: caddy:
image: caddy:latest image: caddy:latest
@@ -597,29 +540,15 @@ services:
- 443:443 - 443:443
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
- /home/shaan/torrent-stack/caddy/Caddyfile:/etc/caddy/Caddyfile - ./caddy/Caddyfile:/etc/caddy/Caddyfile
- /home/shaan/torrent-stack/caddy/site:/srv - ./caddy/site:/srv
- /home/shaan/torrent-stack/caddy/caddy_data:/data - ./caddy/caddy_data:/data
- /home/shaan/torrent-stack/caddy/caddy_config:/config - ./caddy/caddy_config:/config
restart: unless-stopped restart: unless-stopped
scrutiny: # ---------------------------------------------------------------------------
image: ghcr.io/analogj/scrutiny:nightly-omnibus # Karakeep
container_name: scrutiny # ---------------------------------------------------------------------------
cap_add:
- SYS_RAWIO
ports:
- "${SCRUTINY_PORT:-54321}:8080" # webapp
- "${SCRUTINY_ADMIN_PORT:-12345}:8086" # influxDB admin
volumes:
- /run/udev:/run/udev:ro
- ./config:/opt/scrutiny/config
- ./influxdb:/opt/scrutiny/influxdb
devices:
- "/dev/nvme0n1"
- "/dev/sda"
#- "/dev/sdb"
restart: unless-stopped
karakeep: karakeep:
image: ghcr.io/karakeep-app/karakeep:${KARAKEEP_VERSION:-release} image: ghcr.io/karakeep-app/karakeep:${KARAKEEP_VERSION:-release}
@@ -629,17 +558,11 @@ services:
ports: ports:
- 4621:3000 - 4621:3000
volumes: volumes:
# By default, the data is stored in a docker volume called "data".
# If you want to mount a custom directory, change the volume mapping to:
# - /path/to/your/directory:/data
- karakeep-data:/data - karakeep-data:/data
environment: environment:
MEILI_ADDR: http://meilisearch:7700 - MEILI_ADDR=http://meilisearch:7700
BROWSER_WEB_URL: http://chrome:9222 - BROWSER_WEB_URL=http://chrome:9222
# OPENAI_API_KEY: ... - DATA_DIR=/data
# You almost never want to change the value of the DATA_DIR variable.
# If you want to mount a custom directory, change the volume mapping above instead.
DATA_DIR: /data # DON'T CHANGE THIS
restart: unless-stopped restart: unless-stopped
chrome: chrome:
@@ -656,7 +579,7 @@ services:
- --window-size=1440,900 - --window-size=1440,900
restart: unless-stopped restart: unless-stopped
meilisearch: # karakeep vector coord. support for karakeep. allows semantic search meilisearch:
image: getmeili/meilisearch:v1.41.0 image: getmeili/meilisearch:v1.41.0
container_name: karakeep-meilisearch container_name: karakeep-meilisearch
env_file: env_file:
@@ -664,5 +587,5 @@ services:
volumes: volumes:
- meilisearch:/meili_data - meilisearch:/meili_data
environment: environment:
MEILI_NO_ANALYTICS: "true" - MEILI_NO_ANALYTICS="true"
restart: unless-stopped restart: unless-stopped